wincredui.dll

  • File Path: C:\Windows\system32\wincredui.dll
  • Description: Credential Manager User Internal Interface

Hashes

Type Hash
MD5 F4E6813AFB1FF5602CAFD42BCDBA26B3
SHA1 B78D33EB8159306FEF38CADEF6CE0BD9DA540B1D
SHA256 63DF44EF81CE93AE6BAC42D4F6D7BDD4BD14A3E3194256E1F26486FA0CA61090
SHA384 E2292959F8DA85E07484499247DDA7FB85A4E067EC146139A8040C68F8114C0AD40E069B2863BA78C1BB4EC65DAA9EE6
SHA512 7A4FFABAF920DABE8CDE64CA36B03E8F6E1EA3F360E7A996165C5379A9686ED9B1666A2ADFAD3815CF3A5F276B0E0C85D49C55CF788F8D831DEF3F24E82B1828
SSDEEP 3072:jYy4Ltujd3wHxMAKQD3NS90QcyBd8XGNkxcBZY5SYPrss88xMNZ:Myys5gxMAKQ2cdXGNzFYPrsr8xM
IMP 30B490BB4711D10303DAB50A099DBB62
PESHA1 C75A4982CC7C8A54CFBC94597250EA7319613FEC
PE256 B1612C18C63E63A408043FB9A3AA2E0A6184017F4341A15B262A7B0BB8B4E225

DLL Exports:

Function Name Ordinal Type
CredUIInternalPromptForWindowsCredentialsWorker 10 Exported Function
CredUIInternalPromptForWindowsCredentialsW 9 Exported Function
CredUIInternalPromptForWindowsCredentialsA 8 Exported Function
DllCanUnloadNow 11 Exported Function
DllUnregisterServer 14 Exported Function
DllRegisterServer 13 Exported Function
DllGetClassObject 12 Exported Function
CredUIInternalConfirmCredentialsA 3 Exported Function
CredUIInternalCmdLinePromptForCredentialsW 2 Exported Function
CredUIInternalCmdLinePromptForCredentialsA 1 Exported Function
CredUIInternalConfirmCredentialsW 4 Exported Function
CredUIInternalPromptForCredentialsW 7 Exported Function
CredUIInternalPromptForCredentialsA 6 Exported Function
CredUIInternalInitControls 5 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: wincredui.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/63df44ef81ce93ae6bac42d4f6d7bdd4bd14a3e3194256e1f26486fa0ca61090/detection/

Possible Misuse

The following table contains possible examples of wincredui.dll being misused. While wincredui.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_uipromptforcreds_dlls.yml - '\wincredui.dll' DRL 1.0
sigma image_load_uipromptforcreds_dlls.yml - 'wincredui.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.